Why ransomware hits SMBs hardest
Ransomware operators have shifted from targeting large enterprises to SMBs — smaller organizations with fewer defenses, less IT staff, and the same willingness to pay to get their data back. The average SMB ransom demand in 2025 exceeded $200,000. More damaging: the average downtime was 21 days.
The good news is that ransomware is preventable with the right layered stack. No single tool stops it — but the combination below does.
Figure 1 — Four-layer ransomware defense architecture. Each layer independently reduces risk; together they stop the full kill chain.
The ransomware kill chain — and where to break it
| Kill Chain Stage | Attacker Action | Defense That Breaks It |
|---|---|---|
| Initial Access | Phishing email, RDP brute-force, unpatched CVE | Email gateway, MFA, patch management |
| Execution | Malicious macro, PowerShell dropper | EDR behavioral detection, application allowlisting |
| Persistence | Registry keys, scheduled tasks, new admin accounts | EDR rollback, privileged access management |
| Lateral Movement | Pass-the-hash, SMB spread across flat network | VLAN segmentation, least-privilege accounts |
| Exfiltration | Data staged and sent to C2 before encryption | DLP, DNS filtering, CASB |
| Encryption | Files encrypted, ransom note dropped | EDR autonomous rollback (SentinelOne Storyline) |
| Recovery | Attacker demands payment | Immutable backup restore — no payment needed |
Immutable backups: your last line of defense
An immutable backup cannot be encrypted, deleted, or modified — even by a ransomware operator who has compromised your admin credentials. The 3-2-1 rule is the minimum:
- 3 copies of data
- 2 different media types (e.g., local NAS + cloud)
- 1 copy offsite and air-gapped
IDENETY uses Datto for immutable, air-gapped backup with tested restore SLAs. We test restores quarterly — not just assume they work.
Incident response: the 72-hour playbook
When ransomware fires, the first 72 hours determine whether you pay or recover. Your IR plan must answer these questions before an incident:
- Who declares the incident and who is the incident commander?
- Which systems get isolated first (domain controllers, file servers)?
- What is the RTO/RPO for each critical system?
- Who contacts cyber insurance, legal counsel, and law enforcement?
- What is the communication plan for customers and staff?
IDENETY ransomware protection stack
- SentinelOne EDR with autonomous rollback — included in COMPLETE plan.
- Adlumin SIEM with 24/7 SOC monitoring.
- Datto immutable backup with quarterly restore testing.
- VLAN segmentation to contain lateral movement.
- Tabletop IR exercises available as a professional service.
Contact our engineers to assess your current ransomware exposure and build a remediation roadmap.
.png)